scheduler
Audited by Socket on Aug 26, 2026
2 alerts found:
Securityx2The code is a legitimate-looking configurable shell-job runner. It contains significant security risk if job definitions, job names, or workdirs are attacker-controlled because shell=True enables arbitrary command execution, inherited environment variables may expose secrets, and log paths are insufficiently validated in this fragment. No direct evidence of intentional malware or supply-chain sabotage is present. Use trusted, validated job definitions, avoid shell=True where possible, sanitize names, restrict environment variables, and terminate process groups on timeout.
The code appears to implement a scheduler monitoring and control API, not malware. However, exposing it on 0.0.0.0 without authentication allows remote users to disclose job commands, working directories, logs, and runtime state, and to trigger arbitrary registered scheduler jobs. The log filename construction should use strict name validation and containment checks. Restrict network access or add authentication and authorization before deployment. The fragment is incomplete as provided, so full runtime behavior cannot be confirmed.